
CVE-2026-4925 Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own m… https://www.cve.org/CVERecord?id=CVE-2026-4925
Post summary
CVE-2026-4925 reveals an improper access‑control flaw in Devolutions Server’s MFA feature that allows authenticated users to bypass admin restrictions; no PoC, exploit, or active exploitation is reported.
